Skip to main content

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

0
Critical
Vulnerabilityremotercezero-day
Published: 09/23/2026 (09/23/2026, 07:17:23 UTC)
Source: Bleeping Computer

Description

A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP Access Policy Manager (APM) has been exploited in remote code execution attacks. The flaw affects BIG-IP APM instances configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server. Deployments using APM only as an OAuth Client or Resource Server without authorization server profiles are not affected. F5 has released security updates to address this issue and provided an iRule mitigation for those unable to patch immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated remediation by U.S. federal agencies. The vulnerability has been actively exploited, and F5 advises monitoring for indicators such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 07:18:08 UTC

Technical Analysis

CVE-2026-94127 is a critical zero-day vulnerability in F5 BIG-IP APM affecting instances configured as OAuth Authorization Servers with specific access policies and OAuth profiles on virtual servers. The flaw enables remote code execution and has been actively exploited in the wild. F5 has released security updates to fix the vulnerability and provided an iRule mitigation for immediate protection. The vulnerability is tracked by CISA, which has mandated U.S. federal agencies to patch promptly. Deployments using APM solely as OAuth Clients or Resource Servers without authorization server profiles are not vulnerable. Indicators of compromise include multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Shadowserver tracks over 14,700 IPs with BIG-IP APM fingerprints, though the patch status of these is unknown.

Potential Impact

The vulnerability allows remote code execution on affected BIG-IP APM systems configured as OAuth Authorization Servers, potentially enabling attackers to execute arbitrary commands. This poses significant risks to organizations relying on BIG-IP APM for centralized access management, including unauthorized access, network compromise, and data breaches. The flaw has been actively exploited, prompting urgent remediation directives from CISA for U.S. federal agencies. Deployments not configured as OAuth Authorization Servers are not impacted.

Mitigation Recommendations

F5 has released official security updates that fix this vulnerability and should be applied immediately. For environments unable to patch promptly, F5 provides an iRule mitigation available from F5 Support to apply to the affected BIG-IP APM virtual servers. Customers are advised to monitor for indicators of compromise such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Follow F5's official advisory for detailed remediation steps and apply patches as soon as possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.94,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/","fetched":true,"fetchedAt":"2026-09-23T07:17:59.843Z","wordCount":718}

Threat ID: 6ab37d27f7a7c541066f29c3

Added to database: 09/23/2026, 07:17:59 UTC

Last enriched: 09/23/2026, 07:18:08 UTC

Last updated: 09/23/2026, 08:01:37 UTC

Views: 20

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses